Note: This report is updated by a verification record
Malicious package due to embedded executable, arbitrary code execution during install, command injection vulnerabilities, and untrustworthy source project.
Package compromised via npm token leak from phishing attack
Note: This report is updated by a verification record
The package exhibits several suspicious behaviors indicative of malicious intent. Firstly, it contains an embedded executable (node-gyp.dll) with a mismatched extension, suggesting potential obfuscation. Secondly, the install.js script executed during installation allows arbitrary code execution. Finally, the package uses npm install and yarn add in a way that is vulnerable to command injection, where attacker-controlled package names or versions can lead to remote code execution. The low popularity of the source project further increases the risk.